Skip to content

Hide Navigation Hide TOC

Indirect PI — Credential / API Key Exfiltration via Agent Action - ATR-2026-00702 (06b90fe8-5512-553a-a7b8-3e7bb24bd37c)

Detects indirect prompt injection payloads that instruct an agent to locate and exfiltrate credentials, API keys, or stored passwords to an external destination (email, URL, or third-party service). This is distinct from direct credential theft: the payload is embedded in content consumed by the agent (emails, documents, web pages, VPI frames) and the agent is induced to perform the exfiltration as a side-effect of a legitimate task. Source: indirect-pi-exfil-credential / indirect-pi-credential-exfil-carrier / indirect-pi-exfil-credentials-carrier.

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern Indirect PI — Credential / API Key Exfiltration via Agent Action - ATR-2026-00702 (06b90fe8-5512-553a-a7b8-3e7bb24bd37c) Agent Threat Rules 1
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Indirect PI — Credential / API Key Exfiltration via Agent Action - ATR-2026-00702 (06b90fe8-5512-553a-a7b8-3e7bb24bd37c) Agent Threat Rules 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2